Welcome to TK's Web Quest, now fully independent! // Check out some photos of the fall colors from Guanella Pass in the blog! // Now built with 11ty! // Try our new Midnight flavor! // The Worst Webring: Additional slots now open! //
Welcome to TK's Web Quest, now fully independent! // Check out some photos of the fall colors from Guanella Pass in the blog! // Now built with 11ty! // Try our new Midnight flavor! // The Worst Webring: Additional slots now open! //
blog/2026-04-01-human-json.md

blog entry

Trust, Disclosure, and Human.json

Permalink for Trust, Disclosure, and Human.json

A new way to verify web content was made with human hands

I was reading the Scrolls newsletter the other day and one of the links was to the human.json protocol. Around the same time, I read a post by Brennan about Trust and Faith on the Indie Web. This, plus the other devastation wrought by AI got me thinking about my own thoughts about generative AI, disclosure, and trust. I'm not sure I came down on a good, solid answer that I would defend tooth and nail, but I'm hoping that writing about it can help me solidify my thoughts.

First, let's take a look at how platforms are currently handling AI.

...

Yeah. You see it too, right? Almost no one is doing anything about it. Disclosure is often voluntary and even if it was mandatory, it's hard to perfectly spot generative AI in every scenario. Stuff is making it through anyway. Even I was taken in by a youtube channel that was using AI to generate music. I liked the music! I listened to it a lot! But I don't have an ear for AI sound. I didn't even notice this music wasn't human made until it was pointed out to me. Now I can't unhear some of the small tells. It's difficult to prove without a doubt that something is made by a computer or by a human. Even if there were laws regulating AI use or disclosure, they would be hilariously difficult to enforce. So, that leads me to the natural place that a lot of independent creators have landed. As humans, we should declare our humanity by badging everything we make as "Made by Humans" or "No AI." But... Is that really what we should do?

Brennan's stance, further elaborated, is that the badging of human made content declares generative AI as the victor. If we declare ourselves to be human, we are discarding the territory we have held for so long. The default becomes "everything was made with AI unless a human put their sticker on it." It also speaks to a large usage of energy fighting fair when the enemy fights dirty, something that Brennan wrote about previously. If your enemy starts their fight at "We will steal every written word on the internet, regardless of who wrote it," then why should we ever expect them to follow the rules? The internet is built on a series of norms and accepted practices. Standards only exist because people agree they should exist and that they will all interact with the information in accordance to the best practices agreed upon. If the enemy fights dirty, why should we waste effort defending in ways that only work if they play fair?

I absolutely see where Brennan is coming from here. It's genuinely difficult to argue against such an attitude other than by generalizing it. Still, not doing anything rubs me the wrong way. So I looked again at the Human.json protocol. I wanted to understand what it's really doing under the hood and see how hard it would actually be to add it to a site. As it turns out, this is an easy, low effort way to quietly say "I'm human" specifically to people who are looking for it but in a way that is otherwise invisible. It's not a perfect compromise, but I like the direction it takes. I won't repeat the documentation here. It's well written and well reasoned. Here's just a small summary of how it works.

Website creators store a human.json file somewhere. It could be on their website itself. It could be somewhere else. It doesn't matter as long as the file is available over HTTP/S. In that file, they declare their own site's domain and the domains of other sites that they trust are being maintained by humans. Then, in the head tag of their website, they add a link to the file. Not with any text attached, just a reference in a specific format. On the user side, they can use an extension or other program to look for those human.json tags. If one is found, it alerts the user that a human.json exists. The user then gets to decide if they trust the declaration. If they do, then the extension caches the human.json that is linked and any sites that person vouches for will now notify the user too. The interesting thing to me here isn't necessarily just the claims to be human, but that the verification program or extension can use the human.json file itself to follow links deep into the indie web because if site A vouches for site B and Site B also has a human.json, the verifier can look at that file to find more sites that people vouch for and categorize them in terms of how many hops it takes to go from a trusted site to any other given site. The other upshot is that the verifier can show all of the vouched-for sites to the user which basically makes an automated discovery engine and blogroll of human-made sites. The user confirmation is also important. Anyone can add a human.json, so like with disclosures, it's completely voluntary and could be a lie.

Still, though, I like seeing the extension light up when I visit a site that has one. It's a little light kept burning by people who are making the good indie web I love.

About the author

TK

Writer, woodturner, photographer, podcaster, and game designer making cool things on the internet.